Agent Skills: detecting-t1055-process-injection-with-sysmon
Detect process injection techniques (T1055) including classic DLL injection, process hollowing, and APC injection by analyzing Sysmon events for cross-process memory operations, remote thread creation, and anomalous DLL loading patterns.
UncategorizedID: plurigrid/asi/detecting-t1055-process-injection-with-sysmon
165
Install this agent skill to your local
Skill Files
Browse the full folder contents for detecting-t1055-process-injection-with-sysmon.
Loading file tree…
Select a file to preview its contents.